Lucene search

K
saintSAINT CorporationSAINT:33A2B37D85BBED54AEFA19C613995A6F
HistoryAug 07, 2006 - 12:00 a.m.

Microsoft SQL Server Hello buffer overflow

2006-08-0700:00:00
SAINT Corporation
my.saintcorporation.com
26

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.961

Percentile

99.5%

Added: 08/07/2006
CVE: CVE-2002-1123
BID: 5411
OSVDB: 10132

Background

Microsoft SQL Server is a database server package for Windows platforms.

Problem

Microsoft SQL Server 2000 is affected by a buffer overflow vulnerability in the code which handles user authentication. This allows a remote attacker to execute arbitrary commands.

Resolution

Apply the patch referenced in Microsoft Security Bulletin 02-056.

References

<http://www.microsoft.com/technet/security/bulletin/ms02-056.mspx&gt;

Limitations

Exploit works on Microsoft SQL Server 2000 SP2 on Windows 2000.

Platforms

Windows

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.961

Percentile

99.5%